Tomcat Server SSL Installation


  1. Download your certificate files from your certificate authority and save them to the same directory as the keystore that you created during the CSR creation process. The certificate will only work with the same keystore that you initially created the CSR with. The certificates must be installed to your keystore in the correct order.

  1. Install the Root Certificate file: Every time you install a certificate to the keystore you must enter the keystore password that you chose when you generated it. Enter the following command to install the Root certificate file:
keytool -import  -trustcacerts -keystore tomcat.jks -storepass changeit -alias root -file root.cer 
  1. Install the Intermediate Certificate file: If your certificate authority provided an intermediate certificate file, you will need to install it here by typing the following command:
keytool -import  -trustcacerts -keystore tomcat.jks -storepass changeit -alias intermediate  -file intermediate.cer

If successful, you will see "Certificate was added to keystore".
  1. Install the Primary Certificate file: Type the following command to install the Primary certificate file (for your domain name):
keytool -import  -trustcacerts -keystore tomcat.jks -storepass changeit -alias tomcat -file servercertificate.cer 

If successful, you will see "Certificate reply was installed in keystore". You now have all the certificates installed to the keystore file. You just need to configure your server to use the keystore file.

Note:- when given api error then use this protocol     
 “protocol="org.apache.coyote.http11.Http11NioProtocol”



Note:- if you have a pfx file then use this command to make.jks


Convert PFX to keystore.jks

Keytool  -importkeystore -srckeystore uatwebsrv1.pfx -srcstoretype pkcs12 -destkeystore uatwebsrv1.jks  -deststoretype  JKS


Configuring your SSL Connector
Tomcat will first need an SSL Connector configured before it can accept secure connections.
1.    Open the Tomcat server.xml file in a text editor (this is usually located in the conf folder of your Tomcat's home directory).
2.    Find the connector that will be secured with the new keystore and uncomment it if necessary (it is usually a connector with port 443 or 8443 like the example below).
3.    Specify the correct keystore filename and password in your connector configuration. When you are done your connector should look something like this:
<Connector port="443" protocol="HTTP/1.1" maxThreads="150" scheme="https" secure="true" SSLEnabled="true" keystoreFile="conf/tomcat.jks" keystorePass="changeit" clientAuth="false" SSLProtocol="TLSv1+TLSv1.1+TLSv1.2" ciphers="TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA" />
Note: If you are using version 7 of Tomcat you will need to change "keypass" to "keystorePass".
4.    Save your changes to the server.xml file.
5.    Restart Tomcat.



No comments:

Post a Comment